Re: Module Signatures [was Re: On Gaming CPANTS...]

2006-07-07 Thread Tels
Moin, On Thursday 06 July 2006 03:22, Jonathan Rockway wrote: It adds a dependency on a binary application (gpg) that users have to install by hand, doesn't check for the presence of it properly, and if you don't have it, installs an enormous chain of dependencies, with said deps having

Re: Module Signatures [was Re: On Gaming CPANTS...]

2006-07-06 Thread A. Pagaltzis
* Jonathan Rockway [EMAIL PROTECTED] [2006-07-06 03:25]: I think the solution (to dependency hell) is to dictate that CPAN modules be signed with a standard algorithm. OpenPGP allows too many different algorithms, hence the 22 modules Crypt::OpenPGP is dependent on. The only strong reason to